TOCTOU Vulnerability in Containerd Affects Host Filesystem
CVE-2025-47290
What is CVE-2025-47290?
A time-of-check to time-of-use (TOCTOU) vulnerability has been identified in the container runtime, Containerd, specifically in version 2.1.0. This vulnerability occurs during the unpacking process of container images pulled from repositories, allowing specially crafted images to make arbitrary modifications to the host filesystem. Users of Containerd are advised to upgrade to version 2.1.1, which addresses this issue. To mitigate risk, it is crucial to use only trusted images and restrict permissions to trusted users when importing images.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
containerd = 2.1.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
